mediumVulnerability

GHSA-8f6j-263m-g72x

### Summary `SignedDataVerifier` attempts to perform online revocation checking when `enable_online_checks=True`, but its OCSP validation logic accepts stale `GOOD` responses as valid indefinitely. In `appstoreserverlibrary/signed_data_verifier.py`, `_ChainVerifier.check_ocsp_status()` verifies the OCSP response signature and CertID match, but never validates the freshness window carried by `producedAt`, `thisUpdate`, or `nextUpdate`. As a result, a previously valid signed OCSP `GOOD` response can be replayed after it is expired, and the library will still treat the certificate as good. If an App Store signing certificate or intermediate is ever revoked, applications using this library with online checks enabled can continue accepting JWS objects signed with the revoked key as long as a stale signed OCSP response is replayed.

Properties

ghsa_id
GHSA-8f6j-263m-g72x
severity
medium
summary
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
cve_id
GHSA-8f6j-263m-g72x
is_ghsa_only
true
ghsa_published
2026-07-13T23:49:14Z
source_url
https://github.com/advisories/GHSA-8f6j-263m-g72x
ghsa_updated
2026-07-13T23:49:14Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]pip/app-store-server-library

AFFECTS (1)

[Software]pip/app-store-server-library

HAS_WEAKNESS (2)

[Weakness]Improper Check for Certificate Revocation
[Weakness]Improper Certificate Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8f6j-263m-g72x — Ninja Signal Threat Intelligence | Ninja Signal